2023 CVE Vulnerabilities

31,442 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-1239MEDIUM4.8Cross-site Scripting (XSS) - Reflected in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1238MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-1237MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
CVE-2023-23554HIGH8.8Uncontrolled search path element vulnerability exists in pg_ivm versions prior to 1.5.1. When refreshing an IMMV, pg_ivm...
CVE-2023-22847MEDIUM4.3Information disclosure vulnerability exists in pg_ivm versions prior to 1.5.1. An Incrementally Maintainable Materialize...
CVE-2023-1212MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2.
CVE-2023-1211HIGH7.2SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
CVE-2023-27891HIGH7.5rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4....
CVE-2023-0330MEDIUM6A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to m...
CVE-2023-26601HIGH7.5Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Su...
CVE-2023-24217HIGH8.8AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.
CVE-2023-26949CRITICAL9.8An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to ...
CVE-2023-24737MEDIUM6.1PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /ad...
CVE-2023-24736CRITICAL9.8PMB v7.4.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /sauvegarde/restaure_...
CVE-2023-24735MEDIUM6.1PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerabil...
CVE-2023-24734CRITICAL9.8An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbi...
CVE-2023-24733MEDIUM6.1PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /ad...
CVE-2023-1161HIGH7.1ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via pac...
CVE-2023-0093HIGH8.8Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third p...
CVE-2023-26600MEDIUM6.5ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and ...
CVE-2023-24776CRITICAL9.8Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addo...
CVE-2023-24763HIGH8.8In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2...
CVE-2023-27472MEDIUM6.1 quickentity-editor-next is an open source, system local, video game asset editor. In affected versions HTML tags in ent...
CVE-2023-26054MEDIUM6.5BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. I...
CVE-2023-23939HIGH7Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now